[jboss-jira] [JBoss JIRA] (ELY-1950) FORM authentication not working for URL encoded session IDs

Farah Juma (Jira) issues at jboss.org
Wed Jun 10 17:32:03 EDT 2020


     [ https://issues.redhat.com/browse/ELY-1950?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Farah Juma updated ELY-1950:
----------------------------
    Fix Version/s: 1.13.0.CR2
                       (was: 1.13.0.CR1)


> FORM authentication not working for URL encoded session IDs
> -----------------------------------------------------------
>
>                 Key: ELY-1950
>                 URL: https://issues.redhat.com/browse/ELY-1950
>             Project: WildFly Elytron
>          Issue Type: Bug
>          Components: HTTP
>            Reporter: Darran Lofthouse
>            Assignee: Darran Lofthouse
>            Priority: Major
>             Fix For: 1.13.0.CR2
>
>
> The session IDs are encoded as: -
> {code}
> /secure/j_security_check;jsessionid=kVzsBG9c3XxcOlzpa65ohiMeMNqXdSNQuOdvdpR3.flame
> {code}
> However the code that checks if this is a submission to j_security_check is: -
> {code:java}
> request.getRequestURI().getPath().endsWith(postLocation)
> {code}
> This code needs to trim the path at ';'



--
This message was sent by Atlassian Jira
(v7.13.8#713008)


More information about the jboss-jira mailing list